Tego AI disclosed a flaw in Anthropic’s Claude Code that can cause the tool to read files outside a cloned repository and include their contents in the first outbound model request without the warning or approval prompt users would normally expect. The issue abuses a committed CLAUDE.md file containing an @import directive that points to a symbolic link inside the repository; Claude Code validates the in-repo path, but the filesystem resolves the link to an external file such as /etc/passwd, enabling silent data exposure. Tego AI said the behavior was confirmed in Claude Code v2.1.x.
The researchers said the bug reflects the same underlying symlink-check weakness previously addressed in Claude Code under CVE-2025-59829 and CVE-2026-25724, but still reachable through the startup memory loader code path. Anthropic reportedly closed the July 2026 HackerOne report as Informative, maintaining that the product’s “trust this folder” prompt defines the intended security boundary and already grants broad project access. Tego AI disputed that position, warning that predictable sensitive file paths in CI runners, containers, and standardized developer images could make the flaw relevant for enterprise AI coding-agent deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After receiving the July 2026 HackerOne report, Anthropic reportedly closed it as Informative. The company argued that the "trust this folder" prompt is the intended security boundary and that accepting it already grants broad project access.
Tego AI reported a Claude Code issue to Anthropic through HackerOne in July 2026. The flaw involved a CLAUDE.md @import directive pointing to a symlink that could cause out-of-repository file contents to be included in the first outbound model request.
Anthropic had previously fixed similar symlink-related issues in Claude Code tracked as CVE-2025-59829 and CVE-2026-25724, according to Tego AI. The later disclosure said the same underlying symlink-check pattern remained reachable through a different code path.
Tego AI publicly disclosed a Claude Code flaw in which a repository can use a committed CLAUDE.md file with an @import directive to a symbolic link, causing the tool to read a file outside the cloned project and send its contents in the first outbound model request without the expected warning. The behavior was confirmed against Claude Code v2.1.x.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.